Package Health

mwstake/mediawiki-component-dynamicconfig

This is a generally healthy, actively published package with a stable 2.1.2 release, a clear GPL-3.0-only license, documented usage, tests, a coherent 32-file source tree, no registry deprecation, and a non-archived repository with an organizational owner. The main concerns are that only two commits from one contributor were observed in the last 3 months, the repository has very limited popularity and no recent issue or pull-request throughput, and the workflow lacks explicit top-level token permissions; the absence of a security policy and changelog also reduces transparency. These concerns warrant caution but do not outweigh the recent release, repository activity, tests, and organization backing.

Latest 2.1.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

All two recent commits came from one contributor, giving a 100% top-contributor share; this is a genuine continuity concern, though organizational ownership provides some capacity to hand maintenance off.

Repo commit activitycaution

Two commits were recorded in the last 3 months, showing some ongoing activity but a low maintenance pace for the period.

Repo issue activitycaution

There is one open issue and one open pull request, but no issues or pull requests were created or closed in the last month, indicating limited observable community or maintenance throughput.

Repo popularitycaution

The repository has only 2 stars, 0 forks, and 2 watchers. This is weak supporting evidence, but popularity alone is not a decisive health measure for a small specialized component.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a transparency and assurance gap, not evidence that the package is unsafe by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

HalloWelt! GmbH

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ~1.0|~2
—
—
mwstake/mediawiki-componentloader
Version ~1
—
—

Weekly Downloads

Info

Last Published
23 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform